A leak of internal chats allegedly belonging to the Silent Ransom Group (SRG), a Russia-linked extortion operation that targets U.S. law firms and financial institutions, has exposed cryptocurrency wallets that blockchain analytics firm Chainalysis confirms are genuinely tied to the group's operations.

The leak, published on a ransomware-linked website, contains 5,692 messages spanning August 2025 to September 2026. Reuters reported the disclosure on October 7, and Chainalysis said that while it verified the crypto addresses in the material, it could not authenticate the entire collection.

What the Chats Claim

The messages include what purports to be the group's internal deal board, claiming approximately $207 million in payments from 27 firms between April 3 and September 24, 2026, according to DataBreaches.net. Blockchain intelligence firm Crystal Intelligence, which analyzed the leak, relayed the same claimed total while explicitly noting it remains unverified.

The conversations reportedly detail ransom payments, laundering methods and operating expenses — an unusually complete window into a crew that runs extortion campaigns without deploying ransomware encryption at all.

What the Chain Confirms

This is where the story hardens. Chainalysis independently traced several leaked wallets to millions of dollars in extortion proceeds, including one address funded entirely by a single victim payment exceeding $10 million, as ISMG recounted. The firm also identified transfers apparently used to pay people providing services to the group.

The Register, reporting October 8, noted the key nuance: some wallet addresses in the material match Chainalysis's existing intelligence on the group, lending the leak credibility, even though the analytics firm could not vouch for every message. On-chain evidence supports the scale of the operation, if not the exact $207 million total.

The Group's Method

SRG — also tracked as Luna Moth and Chatty Spider, and described by researchers as a Conti offshoot — typically steals confidential data by impersonating IT support staff over the phone, then threatens to publish it unless victims pay. More recently, according to the leaked material, the group has escalated to in-person visits to victims' offices, sending representatives to pressure firms physically.

For law firms and financial institutions, the takeaway is that the initial compromise is social engineering, not malware: reception-level controls on walk-in visitors and verification procedures for anyone claiming to be IT staff are the actual attack surface. For everyone else, the leak is a reminder that extortion economics now run on crypto rails — and that when internal operational chats leak, the blockchain can corroborate the receipts.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.